Application Security Analyst — Secure SDLC & Cloud (Hybrid)

Rest

Sydney, City of Melbourne

Hybrid

AUD 120,000 - 170,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

5 Rest Days (wellbeing days)
Paid parental leave (22 weeks)
Learning and development opportunities
Income Protection Insurance
Additional leave options

Job summary

Rest is seeking an Application Security Analyst on an 18 Month Fixed Term Contract to strengthen security of applications, APIs and software delivery. You will work closely with engineering and product teams to embed secure practices and lead secure development efforts.

Responsibilities include running security assessments, threat modelling, and driving tooling and secure delivery across cloud-native environments, with a focus on delivering measurable risk reductions for millions of Australians.

Qualifications

  • Experience in application security, DevSecOps or secure software development within a complex enterprise environment.
  • Experience conducting application security assessments across web applications, APIs and cloud-native environments.
  • Strong knowledge of OWASP Top 10, secure coding principles, threat modelling and vulnerability management.
  • Hands-on experience with SAST, DAST, SCA, API security testing and secrets detection.
  • Familiarity with security frameworks and standards such as OWASP ASVS, OWASP SAMM, NIST CSF and APRA CPS 234.
  • Understanding of CI/CD pipelines and cloud platforms, ideally AWS.
  • Good communication skills to translate findings into actionable recommendations.

Responsibilities

  • Lead application security assessments across web applications, APIs and cloud-based services, identifying risks and remediation plans.
  • Partner with engineering and architecture teams to embed security into solution design via threat modelling.
  • Validate and manage findings, prioritise remediation, and distinguish genuine risks from false positives.
  • Drive tooling and process improvements for SAST, DAST, SCA, API security testing and secrets detection.
  • Promote secure SDLC and DevSecOps practices, integrating controls into CI/CD pipelines.
  • Coordinate penetration testing activities and oversight remediation outcomes.
  • Develop and maintain application security standards, guardrails and secure development practices.
  • Provide security guidance and enablement to developers and security champions.

Skills

Application Security
DevSecOps
Threat Modelling
SAST
DAST
SCA
API Security
Secure SDLC
CI/CD
Cloud Security

Education

Bachelor's degree in Computer Science

Tools

OWASP ASVS
OWASP SAMM
NIST CSF
APRA CPS 234

Job description

Rest is seeking an Application Security Analyst on an 18 Month Fixed Term Contract to strengthen security of applications, APIs and software delivery. You will work closely with engineering and product teams to embed secure practices and lead secure development efforts.

Responsibilities include running security assessments, threat modelling, and driving tooling and secure delivery across cloud-native environments, with a focus on delivering measurable risk reductions for millions of Australians.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Analyst: DevSecOps & Secure SDLC (18-Month FTC)
Application Security Analyst: DevSecOps & Secure SDLC (18-Month FTC)

Rest • Sydney

Hybrid
AUD 140,000 - 210,000
Hybrid working
5 Rest Days (wellbeing days)
Paid parental leave (22 weeks)
+3
Application Security Lead - Hybrid (18-Month FTC)
Application Security Lead - Hybrid (18-Month FTC)

Rest Super • Sydney, City of Melbourne

Hybrid
AUD 120,000 - 160,000
5 Rest Days
Parental leave 22 weeks
AI & Data Academy
+3
Hybrid App Security Penetration Tester | Secure SDLC Lead
Hybrid App Security Penetration Tester | Secure SDLC Lead

Australia Post • City of Yarra

Hybrid
AUD 110,000 - 170,000
Flexible working
Hybrid work arrangement
Home-office two days per week
AppSec Engineer - Hybrid, Secure Coding & SDLC
AppSec Engineer - Hybrid, Secure Coding & SDLC

ASX Limited • Australia

Hybrid
AUD 120,000 - 180,000
Hybrid working options
AWS Cloud Security Engineer – 12-Month Hybrid Contract
AWS Cloud Security Engineer – 12-Month Hybrid Contract

Rest • Sydney

Hybrid
AUD 120,000 - 150,000
Rest Days
Parental Leave
Learning & Development
+3
Business Analyst
Business Analyst

Michael Page Australia • Sydney

Hybrid
AUD 148,000 - 221,000
Competitive day-rate
Hybrid work arrangements
Sydney-based temporary assignments
Business Analyst: Secure Coding & Application Security
Business Analyst: Secure Coding & Application Security

XPT Software Australia Pty Ltd • Sydney

On-site
AUD 110,000 - 170,000
Business Analyst - Application Security
Business Analyst - Application Security

Whizdom • Sydney

On-site
AUD 90,000 - 120,000
Endpoint Security Engineer — 12-Month Hybrid Contract
Endpoint Security Engineer — 12-Month Hybrid Contract

Rest • Sydney

Hybrid
AUD 120,000 - 160,000
5 Rest Days (wellbeing days)
Parental leave 22 weeks
Learning and development
+3
DevSecOps Business Analyst - Secure SDLC & Automation Lead
DevSecOps Business Analyst - Secure SDLC & Automation Lead

XPT Software Australia • Sydney

On-site
AUD 110,000 - 160,000